← All posts

Test Breached Passwords Blocking Signups with Fake Signup

· FakeSignup
QAsecuritytestingpasswords

When testing signups that block compromised or commonly used passwords, you need a way to quickly generate accounts that bypass these checks. This often involves using temporary email addresses and phone numbers. Fake Signup helps here by providing a disposable email inbox and a temporary phone number for OTPs, allowing you to create new test accounts rapidly even when specific password policies are in place. You can then use these credentials to submit the form and check the signup flow.

Handling Have I Been Pwned Signup QA

Have I Been Pwned (HIBP) or similar k-anonymity checks are common on signup forms. These systems flag accounts using email addresses or passwords previously found in data breaches. For QA, this means your standard test credentials might be rejected. You'll need to generate unique, non-breached credentials for each test. This is where a tool that provides disposable email and phone numbers becomes essential. By using Fake Signup, you can generate a new email and phone for each test run, ensuring your test accounts are not flagged by these checks.

Setting Up Fake Signup for Testing

To begin testing signups that use HIBP checks, you'll need the Fake Signup extension. This extension handles both the temporary email generation and the OTP inbox, so you don't need separate tools for these functions.

  1. Install the Extension:
    • Go to the Chrome Web Store and search for "Signup Tester - Temp Mail & OTP Inbox" or navigate directly using this link: FakeSignup on the Chrome Web Store.
    • Click "Add to Chrome".
  2. Open the Extension:
    • Click the Fake Signup icon in your Chrome toolbar.
    • This will open the extension's inbox panel, where your temporary email address and any received codes will appear.
  3. Generate Credentials:
    • Within the Fake Signup panel, you can click to copy a new temporary email address.
    • There's also an option to generate a temporary phone number for OTPs.

Simulating Signup with Non-Breached Credentials

Once Fake Signup is set up, you can integrate it into your testing process. The key is to generate a fresh email and phone number for each test case, especially when dealing with HIBP checks.

  • New Email for Each Test: Before filling out the signup form, generate a new temporary email address from Fake Signup. Copy this address and paste it into the email field on the signup page.
  • Temporary Phone for OTP: If the signup requires an OTP, generate a temporary phone number from Fake Signup. Enter this number into the phone field.
  • Unique, Non-Breached Password: Crucially, do not reuse standard test passwords like "password123" or any known breached password. Generate a unique, strong password for each test account. You can use a password manager or a simple generation method for this. The combination of a fresh email and a unique, non-breached password should bypass HIBP checks.
  • Submit and Verify: Submit the signup form. If an OTP is required, it should arrive in the Fake Signup inbox panel. Copy the code and enter it on the signup page to complete the registration.

Testing Password Policies Beyond HIBP

While HIBP checks are common, other password policies can also impact your QA. This includes minimum length, complexity requirements (uppercase, lowercase, numbers, symbols), and prohibitions against common dictionary words. Fake Signup doesn't directly generate passwords, but it facilitates the creation of the necessary accounts to test these policies. You generate the email and phone via Fake Signup, then use a separate method for creating compliant passwords.

If a signup requires email verification, the verification link will arrive in the Fake Signup inbox. Clicking this link will usually confirm the email address and activate the account, allowing you to proceed with further testing. This entire process, from generating a temporary email to receiving an OTP or verification link, can be done quickly without needing to switch browser tabs or manage multiple email clients.

Automating with Full Auto (Premium Feature)

For high-volume testing or integration into automated test suites, the Full Auto feature in Fake Signup can be very useful. This premium functionality allows for the automatic processing of signups, including form filling, OTP retrieval, and link clicking. When testing HIBP-blocked signups in an automated fashion, Full Auto can generate fresh credentials for each run, ensuring your automated tests are not blocked by previously used or compromised test data. Saved accounts from these automated runs are stored locally in Chrome's storage, allowing for quick re-use if needed without re-generating credentials. This is particularly helpful for smoke tests or when you need to quickly spin up a batch of test users.